It's easier to rule out undetectable-by-google data exfilteration if the app can only connect to Google.
The obvious way around this is to make a Google-only edition.
Yuck.
It's easier to rule out undetectable-by-google data exfilteration if the app can only connect to Google.
The obvious way around this is to make a Google-only edition.
Yuck.
In fact, in Google's guidance on this subject, they say:
> Local client applications that only allow user-configured transmissions of Restricted Scope data from the device may be exempt from this requirement [to get a Letter of Assessment].
And in another FAQ:
> Local Data Storage: Local client applications don't need to undergo a security assessment because data is run, stored, and processed only on the user's device. Local client applications that only allow user-configured transmissions of Restricted Scope data from the device may be exempt from this requirement.
My feeling is that the author of Pegasus Mail has checked a checkbox incorrectly somewhere, or alternatively has not implemented the desktop oauth2 flow correctly.
My unfounded guess is that just like the parent here, OP isn’t very knowledgeable about OAuth and chose the wrong flow.